Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
320e60c9 by Salvatore Bonaccorso at 2026-08-16T07:59:37+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -11,27 +11,27 @@ CVE-2026-73631 (Exposure of data element to wrong session
vulnerability in the J
- libstruts1.2-java <removed>
NOTE: https://cwiki.apache.org/confluence/display/WW/S2-070
CVE-2026-19906 (A weakness has been identified in pkp pkp-lib
3.3.0/3.4.0/3.5.0. This ...)
- TODO: check
+ NOT-FOR-US: pkp-lib
CVE-2026-19905 (A weakness has been identified in Jinher OA 1.0. Impacted is
an unknow ...)
- TODO: check
+ NOT-FOR-US: Jinher OA
CVE-2026-19904 (A vulnerability was found in SourceCodester Online Book Store
System 1 ...)
NOT-FOR-US: SourceCodester
CVE-2026-19903 (A vulnerability has been found in SourceCodester Online
Clothing Store ...)
NOT-FOR-US: SourceCodester
CVE-2026-19901 (A security flaw has been discovered in LB-LINK X-PRO
1.0.22-20231206. ...)
- TODO: check
+ NOT-FOR-US: LB-LINK
CVE-2026-19900 (A vulnerability was identified in LB-LINK X-PRO
1.0.22-20231206. The i ...)
- TODO: check
+ NOT-FOR-US: LB-LINK
CVE-2026-19899 (A vulnerability was determined in SourceCodester Class and
Exam Timeta ...)
NOT-FOR-US: SourceCodester
CVE-2026-19898 (A vulnerability was found in VictoriaMetrics up to 1.146.0.
Impacted i ...)
- TODO: check
+ NOT-FOR-US: VictoriaMetrics
CVE-2026-19897 (A vulnerability has been found in mangroup dtale up to 3.22.0.
This is ...)
- TODO: check
+ NOT-FOR-US: mangroup dtale
CVE-2026-19896 (A flaw has been found in mangroup dtale up to 3.22.0. This
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: mangroup dtale
CVE-2026-19895 (A vulnerability was detected in opensourcepos Open Source
Point of Sal ...)
- TODO: check
+ NOT-FOR-US: opensourcepos Open Source Point of Sale
CVE-2026-19894 (A security flaw has been discovered in itsourcecode Hospital
Managemen ...)
NOT-FOR-US: itsourcecode System
CVE-2026-19893 (A vulnerability was identified in D-Link DIR-842 2.01.B04.
This impact ...)
@@ -674,11 +674,11 @@ CVE-2026-34492 (External control of file name or path
vulnerability in Johnson C
CVE-2026-27871 (Cwe-327 Use of a Broken or Risky Cryptographic Algorithm
vulnerability ...)
NOT-FOR-US: Johnson Controls
CVE-2026-19910 (PAX Technology Q80 Application Installer Signature
Verification Bypass ...)
- TODO: check
+ NOT-FOR-US: PAX Technology Q80 Application Installer
CVE-2026-19909 (PAX Technology Q80 AIP File Parsing Link Following Remote Code
Executi ...)
- TODO: check
+ NOT-FOR-US: PAX Technology Q80
CVE-2026-19908 (PAX Technology Q80 XCB Daemon Missing Authentication
Vulnerability. Th ...)
- TODO: check
+ NOT-FOR-US: PAX Technology Q80
CVE-2026-18932
REJECTED
CVE-2026-18807 (The ECS WordPress plugin before 4.3.8 does not have
capability or own ...)
@@ -4751,13 +4751,13 @@ CVE-2026-49986 (The Cortex MCP server
(`neuro-cortex-memory`), a cross-platform
CVE-2026-49826 (Concourse is a container-based automation system written in
Go. Prior ...)
NOT-FOR-US: Concourse
CVE-2026-49457 (erlang_quic is a pure Erlang QUIC implementation. Prior to
version 1.4 ...)
- TODO: check
+ NOT-FOR-US: erlang_quic
CVE-2026-49282 (Capstone is a disassembly framework. Prior to version
6.0.0-Alpha9, Ca ...)
TODO: check
CVE-2026-49263 (Capstone is a disassembly framework. Prior to version
6.0.0-Alpha9, Ca ...)
TODO: check
CVE-2026-48528 (Metacat is data repository software that helps researchers
preserve, s ...)
- TODO: check
+ NOT-FOR-US: Metacat
CVE-2026-46603 (VP8L decoding in golang.org/x/image/vp8l can allocate an
excessive amo ...)
TODO: check
CVE-2026-46439 (compliance-trestle is a tooling platform for managing
compliance as co ...)
@@ -4773,9 +4773,9 @@ CVE-2026-19880 (Path-traversal vulnerability in QOS.CH
Sarl Logback-classic on J
CVE-2026-19879 (A flaw was found in Undertow, an HTTP server, within its HTTP
response ...)
TODO: check
CVE-2026-19871 (Use of Hard-coded Credentials in the human resources component
in Rosk ...)
- TODO: check
+ NOT-FOR-US: Roskus Prospero Flow CRM
CVE-2026-19870 (Authorization Bypass Through User-Controlled Key in the
payroll module ...)
- TODO: check
+ NOT-FOR-US: Roskus Prospero Flow CRM
CVE-2026-19847 (A security flaw has been discovered in TOTOLINK A800R
4.1.2cu.5137_B20 ...)
NOT-FOR-US: TOTOLINK
CVE-2026-19846 (A vulnerability was identified in TOTOLINK A800R
4.1.2cu.5137_B2020073 ...)
@@ -4801,13 +4801,13 @@ CVE-2026-19834 (A vulnerability was determined in
Webkul Bagisto up to 2.4.4. Af
CVE-2026-19830 (A vulnerability was found in TRENDnet TEW-816DRM
GURNC4.OT182B-C-TN-R1 ...)
NOT-FOR-US: TRENDnet
CVE-2026-19829 (A security flaw has been discovered in 648540858
wvp-GB28181-pro 2.7.4 ...)
- TODO: check
+ NOT-FOR-US: 648540858 wvp-GB28181-pro
CVE-2026-19828 (A vulnerability was identified in 648540858 wvp-GB28181-pro
2.7.4-2026 ...)
- TODO: check
+ NOT-FOR-US: 648540858 wvp-GB28181-pro
CVE-2026-19827 (A flaw has been found in alldatacenter alldata up to 0.6.8.
This impac ...)
- TODO: check
+ NOT-FOR-US: alldatacenter alldata
CVE-2026-19826 (A vulnerability was detected in alldatacenter alldata up to
0.6.8. Thi ...)
- TODO: check
+ NOT-FOR-US: alldatacenter alldata
CVE-2026-19825 (A security vulnerability has been detected in SourceCodester
Simple Cl ...)
NOT-FOR-US: SourceCodester
CVE-2026-19824 (A weakness has been identified in Tenda W20E
15.11.0.6(1068_1546_841)_ ...)
@@ -5134,9 +5134,9 @@ CVE-2026-49096 (Uncaught Exception (CWE-248) in Kibana
Cases can lead to denial
CVE-2026-49089 (Allocation of Resources Without Limits or Throttling (CWE-770)
in Kiba ...)
TODO: check
CVE-2026-45774 (compliance-trestle is a tooling platform for managing
compliance as co ...)
- TODO: check
+ NOT-FOR-US: compliance-trestle
CVE-2026-45725 (compliance-trestle is a tooling platform for managing
compliance as co ...)
- TODO: check
+ NOT-FOR-US: compliance-trestle
CVE-2026-3883
REJECTED
CVE-2026-19811 (A security flaw has been discovered in TOTOLINK A800R
4.1.2cu.5137_B20 ...)
@@ -5154,39 +5154,39 @@ CVE-2026-19788 (A vulnerability was found in Tenda
AC1206 15.03.06.23_multi_TD01
CVE-2026-19787 (A vulnerability was determined in SourceCodester Air Cargo
Management ...)
NOT-FOR-US: SourceCodester
CVE-2026-19786 (A vulnerability was found in francoisjacquet RosarioSIS up to
12.8. Th ...)
- TODO: check
+ NOT-FOR-US: francoisjacquet RosarioSIS
CVE-2026-19785 (A vulnerability has been found in francoisjacquet RosarioSIS
up to 12. ...)
- TODO: check
+ NOT-FOR-US: francoisjacquet RosarioSIS
CVE-2026-19784 (A flaw has been found in francoisjacquet RosarioSIS up to
12.8. This a ...)
- TODO: check
+ NOT-FOR-US: francoisjacquet RosarioSIS
CVE-2026-19771 (A vulnerability was identified in Baicells EG3661M
BaiCE_BQ6_2.0.5.3_N ...)
- TODO: check
+ NOT-FOR-US: Baicells EG3661M
CVE-2026-19770 (A vulnerability was identified in feedmob fm-mcp-servers
0.0.3. Affect ...)
- TODO: check
+ NOT-FOR-US: feedmob fm-mcp-servers
CVE-2026-19767 (A weakness has been identified in itsourcecode Hospital
Management Sys ...)
NOT-FOR-US: itsourcecode System
CVE-2026-19765 (A security flaw has been discovered in eyaushev
swagger-testcase-mcp 5 ...)
- TODO: check
+ NOT-FOR-US: eyaushev swagger-testcase-mcp
CVE-2026-19764 (A vulnerability was identified in Raisecom Communication
Command and D ...)
- TODO: check
+ NOT-FOR-US: Raisecom Communication Command and Dispatch Management
Platform
CVE-2026-19763 (A vulnerability was determined in DTStack Taier 1.4.0.
Affected by thi ...)
- TODO: check
+ NOT-FOR-US: DTStack Taier
CVE-2026-19762 (A vulnerability was found in DTStack Taier 1.4.0. Affected by
this vul ...)
- TODO: check
+ NOT-FOR-US: DTStack Taier
CVE-2026-19761 (A vulnerability has been found in DTStack Taier 1.4.0.
Affected is the ...)
- TODO: check
+ NOT-FOR-US: DTStack Taier
CVE-2026-19758 (A vulnerability was determined in dromara lamp-cloud up to
5.10.0. Thi ...)
- TODO: check
+ NOT-FOR-US: dromara lamp-cloud
CVE-2026-19757 (A vulnerability was found in Dromara lamp-cloud up to 5.10.0.
This vul ...)
- TODO: check
+ NOT-FOR-US: Dromara lamp-cloud
CVE-2026-19756 (A vulnerability has been found in Dromara lamp-cloud up to
5.10.0. Thi ...)
- TODO: check
+ NOT-FOR-US: Dromara lamp-cloud
CVE-2026-19753 (A vulnerability was detected in Model Context Protocol
mcp-rdf-explore ...)
- TODO: check
+ NOT-FOR-US: Model Context Protocol mcp-rdf-explorer
CVE-2026-19752 (A vulnerability was found in EnzoVezzaro mcp-dominican-layer
up to 39d ...)
- TODO: check
+ NOT-FOR-US: EnzoVezzaro mcp-dominican-layer
CVE-2026-19751 (A flaw has been found in EnzoVezzaro mcp-dominican-layer up to
39dd373 ...)
- TODO: check
+ NOT-FOR-US: EnzoVezzaro mcp-dominican-layer
CVE-2026-19750 (A flaw has been found in Tenda CH, CP and TX3
V21.x/V22.x/V25.x/V26.x/ ...)
NOT-FOR-US: Tenda
CVE-2026-19749 (A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3,
CP3 Pro, C ...)
@@ -5196,9 +5196,9 @@ CVE-2026-19748 (A security vulnerability has been
detected in Tenda CH7, CH7G, C
CVE-2026-19747 (A weakness has been identified in Tenda CH7, CH7G, CH10, CP3,
CP3 Pro, ...)
NOT-FOR-US: Tenda
CVE-2026-19746 (A vulnerability has been found in Calix GigaSpire 26.1.0. The
affected ...)
- TODO: check
+ NOT-FOR-US: Calix GigaSpire
CVE-2026-19745 (A flaw has been found in Calix GigaSpire 26.1.0. Impacted is
an unknow ...)
- TODO: check
+ NOT-FOR-US: Calix GigaSpire
CVE-2026-19617 (A flaw was found in libdm. A local attacker could craft a
malicious Lo ...)
TODO: check
CVE-2026-19483 (IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through
6.0.1.0 ...)
@@ -6080,9 +6080,9 @@ CVE-2026-23603 (Blind SSRF in OAuth2 avatar
synchronization via unvalidated OIDC
CVE-2026-21832 (HCL AION is affected by a vulnerability where indirect prompt
injectio ...)
NOT-FOR-US: HCL
CVE-2026-19744 (Cross-site Scripting in the Markdown renderer in maalfer
Pentestify be ...)
- TODO: check
+ NOT-FOR-US: maalfer Pentestify
CVE-2026-19734 (Missing Authorization and Authorization Bypass Through
User-Controlled ...)
- TODO: check
+ NOT-FOR-US: Roskus Prospero Flow CRM
CVE-2026-19730 (The 'podman quadlet install --replace' command opens the
existing dest ...)
TODO: check
CVE-2026-19716 (Stored Cross-site Scripting (CWE-79) in the user management
component ...)
@@ -6662,17 +6662,17 @@ CVE-2026-49473
(@cedar-policy/authorization-for-expressjs is an open-source Expr
CVE-2026-49466 (Draft List is a WordPress plugin to manage and promote
unpublished con ...)
NOT-FOR-US: WordPress plugin
CVE-2026-48791 (sigstore-java is a sigstore java client for interacting with
sigstore ...)
- TODO: check
+ NOT-FOR-US: sigstore-java
CVE-2026-47718 (FUXA is a web-based Process Visualization
(SCADA/HMI/Dashboard) softwa ...)
- TODO: check
+ NOT-FOR-US: FUXA
CVE-2026-47717 (FUXA is a web-based Process Visualization
(SCADA/HMI/Dashboard) softwa ...)
- TODO: check
+ NOT-FOR-US: FUXA
CVE-2026-46731 (Dell Display and Peripheral Manager (DDPM Windows), versions
prior to ...)
NOT-FOR-US: Dell / EMC
CVE-2026-46688 (The Meeting Room Booking System (MRBS) is a PHP-based
application for ...)
- TODO: check
+ NOT-FOR-US: Meeting Room Booking System (MRBS)
CVE-2026-46382 (The Meeting Room Booking System (MRBS) is a PHP-based
application for ...)
- TODO: check
+ NOT-FOR-US: Meeting Room Booking System (MRBS)
CVE-2026-3835 (The Prevent Direct Access \u2013 Protect WordPress Files plugin
for Wo ...)
NOT-FOR-US: WordPress plugin
CVE-2026-19657 (ScadaLTS 2.7.8.1reflects user-supplied input into an HTML
response wit ...)
@@ -7127,7 +7127,7 @@ CVE-2026-49467 (Pingvin Share X is a secure and easy
self-hosted file sharing pl
CVE-2026-49349 (regclient is a Docker and OCI Registry Client in Go. Prior to
version ...)
TODO: check
CVE-2026-49262 (In the Aimeos Pagible content management system prior to
version 0.10. ...)
- TODO: check
+ NOT-FOR-US: Aimeos Pagible content management system
CVE-2026-48554 (Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are
vulnerable ...)
TODO: check
CVE-2026-48553 (Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are
vulnerable ...)
@@ -7157,9 +7157,9 @@ CVE-2026-47227 (Admidio is an open-source user management
solution. `modules/cat
CVE-2026-47226 (Admidio is an open-source user management solution. Prior to
version 5 ...)
NOT-FOR-US: Admidio
CVE-2026-44741 (Pimcore's Admin Classic Bundle provides a Backend UI for
Pimcore. Vers ...)
- TODO: check
+ NOT-FOR-US: Pimcore
CVE-2026-42018 (JFrog Artifactory could return an internal anonymous-user
token to an ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-26035 (An Improper Authentication vulnerability [CWE-287]
vulnerability in Fo ...)
NOT-FOR-US: Fortinet
CVE-2026-19548 (Multiple Use-After-Free vulnerabilities were found in the
add_archive_ ...)
@@ -7596,7 +7596,7 @@ CVE-2026-5917 (libgit2 versions v0.27.0 through v1.9.0
built with the libssh2 SS
CVE-2026-55676 (Malcolm is a network traffic analysis tool suite. The
file-upload comp ...)
NOT-FOR-US: Malcolm
CVE-2026-48813 (Flawfinder is a a static analysis tool for finding
vulnerabilities in ...)
- TODO: check
+ NOT-FOR-US: Flawfinder
CVE-2026-48804 (python-socketio is a Python implementation of the Socket.IO
realtime c ...)
TODO: check
CVE-2026-48765 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0
allow a lo ...)
@@ -9139,7 +9139,7 @@ CVE-2026-48809 (python-engineio is a Python
implementation of the Engine.IO real
CVE-2026-48802 (python-engineio is a Python implementation of the Engine.IO
realtime c ...)
TODO: check
CVE-2026-48790 (Turso CLI is the command line interface (CLI) to the
open-source datab ...)
- TODO: check
+ NOT-FOR-US: Turso CLI
CVE-2026-48771 (ishankportfolio is a portfolio website. Prior to version
1.0.1, contac ...)
NOT-FOR-US: ishankportfolio
CVE-2026-48767 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0
allow a lo ...)
@@ -9225,9 +9225,9 @@ CVE-2026-48375 (ColdFusion is affected by an Incorrect
Authorization vulnerabili
CVE-2026-48362 (ColdFusion is affected by an Improper Neutralization of
Special Elemen ...)
NOT-FOR-US: Adobe
CVE-2026-48056 (Streambert is a cross-platform Electron Desktop App to stream
and down ...)
- TODO: check
+ NOT-FOR-US: Streambert
CVE-2026-48046 (Streambert is a cross-platform Electron Desktop App to stream
and down ...)
- TODO: check
+ NOT-FOR-US: Streambert
CVE-2026-47940 (Lightroom Classic is affected by an Integer Overflow or
Wraparound vul ...)
NOT-FOR-US: Adobe
CVE-2026-47922 (CAI Content Credentials is affected by a Server-Side Request
Forgery ( ...)
@@ -9245,21 +9245,21 @@ CVE-2026-47285 (Improper neutralization of special
elements used in a command ('
CVE-2026-46670 (YesWiki is a wiki system written in PHP. Prior to version
4.6.4, an u ...)
NOT-FOR-US: YesWiki
CVE-2026-43606 (Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA
secp256 ...)
- TODO: check
+ NOT-FOR-US: AMD
CVE-2026-42976 (Missing authentication for critical function in Windows RPC
API allows ...)
NOT-FOR-US: Microsoft
CVE-2026-42142 (TypeBot is a chatbot builder tool. Prior to version 3.17.0,
the `handl ...)
- TODO: check
+ NOT-FOR-US: TypeBot
CVE-2026-40375 (Missing authorization in Dynamics Business Central allows an
authorize ...)
NOT-FOR-US: Microsoft
CVE-2026-39452 (Protection mechanism failure for some Intel(R) Transfer
Learning Tool ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-35502 (Deserialization of untrusted data for some Intel(R) Extension
for PyTo ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-34635 (is affected by a Use of Hard-coded Cryptographic Key
vulnerability tha ...)
NOT-FOR-US: Adobe
CVE-2026-34175 (Uncontrolled search path for some
Hardware-Aware-Automated-MachineLear ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-33922 (A path traversal vulnerability was discovered in the Offline
archives ...)
NOT-FOR-US: Nozomi Arc
CVE-2026-33921 (The Windows installer deployed Npcap leaving its access
restriction op ...)
@@ -9267,13 +9267,13 @@ CVE-2026-33921 (The Windows installer deployed Npcap
leaving its access restrict
CVE-2026-32791 (Untrusted search path for some Intel(R) Performance Counter
Monitor (I ...)
NOT-FOR-US: Intel
CVE-2026-32788 (Uncontrolled search path for some Approximate Bayesian
Inference Frame ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-32677 (Path traversal for some gaudi-container-runtime before version
1.24.0 ...)
NOT-FOR-US: gaudi-container-runtime
CVE-2026-28757 (Protection mechanism failure for some Intel(R) Workload
Services Frame ...)
NOT-FOR-US: Intel
CVE-2026-28729 (Integer overflow in the UEFI firmware for the Intel(R) Slim
Bootloader ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-28707 (Protection mechanism failure for some LLM-on-Ray before
version 1.0 wi ...)
NOT-FOR-US: Intel
CVE-2026-28700 (Uncontrolled search path for some EquiTriton before version
f5ddbb5 wi ...)
@@ -9285,21 +9285,21 @@ CVE-2026-27302 (Adobe Campaign Classic (ACC) is
affected by an Incorrect Authori
CVE-2026-25652 (is affected by an Incorrect Authorization vulnerability that
could res ...)
NOT-FOR-US: Adobe
CVE-2026-25194 (Out-of-bounds write in the firmware for the Intel(R) Slim
Bootloader m ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-24911 (Stack-based buffer overflow for some Intel(R) PROSet/Wireless
WiFi Sof ...)
NOT-FOR-US: Intel
CVE-2026-24693 (Protection mechanism failure for some Intel(R) oneCCL Bindings
for PyT ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-24099 (Use after free for some Intel(R) PROSet/Wireless WiFi Software
for Win ...)
NOT-FOR-US: Intel
CVE-2026-22887 (Improper buffer restrictions for some Intel(R) PROSet/Wireless
WiFi So ...)
NOT-FOR-US: Intel
CVE-2026-21400 (Protection mechanism failure for some Intel(R) AI Reference
Models bef ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-21399 (Heap-based buffer overflow for the Intel(R) Open Volume Kernel
Library ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-21387 (Protection mechanism failure for some Intel(R) LLM Library for
PyTorch ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-21279 (is affected by an Improper Input Validation vulnerability that
could r ...)
NOT-FOR-US: Adobe
CVE-2026-21273 (is affected by an Improper Input Validation vulnerability that
could r ...)
@@ -9313,9 +9313,9 @@ CVE-2026-20908 (Time-of-check time-of-use race condition
for the Intel(R) NPU Dr
CVE-2026-20906 (Protection mechanism failure for some Intel(R) Neural
Compressor softw ...)
NOT-FOR-US: Intel
CVE-2026-20903 (Protection mechanism failure for some Intel(R) AI Containers
before ve ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-20898 (Improper access control in the firmware for some in Alias
Checking Tru ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-20891 (Improper authentication for some Intel(R) PROSet/Wireless WiFi
Softwar ...)
NOT-FOR-US: Intel
CVE-2026-20890 (Improper privilege management for some Intel(R)
PROSet/Wireless WiFi S ...)
@@ -9323,11 +9323,11 @@ CVE-2026-20890 (Improper privilege management for some
Intel(R) PROSet/Wireless
CVE-2026-20886 (Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi
Software fo ...)
NOT-FOR-US: Intel
CVE-2026-20885 (Improper authentication in the Intel(R) TDX module for some
Intel(R) p ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-20878 (Null pointer dereference for some Intel(R) PROSet/Wireless
WiFi Softwa ...)
NOT-FOR-US: Intel
CVE-2026-20799 (Untrusted search path for some Battery Life Diagnostic Tool
software b ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-20795 (Improper buffer restrictions for some Intel(R) PROSet/Wireless
WiFi So ...)
NOT-FOR-US: Intel
CVE-2026-20789 (Improper access control for some Intel(R) PROSet/Wireless WiFi
Softwar ...)
@@ -9345,9 +9345,9 @@ CVE-2026-20778 (Out-of-bounds read for some Intel(R)
PROSet/Wireless WiFi Softwa
CVE-2026-20776 (Improper conditions check for some Intel(R) PROSet/Wireless
WiFi Softw ...)
TODO: check
CVE-2026-20775 (Uncaught exception for some Intel(R) TDX modules within Ring
0: Trust ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-20770 (Protection mechanism failure for some Cluster Management
Toolkit for K ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-20769 (Improper conditions check for the Intel(R) NPU Driver for all
versions ...)
TODO: check
CVE-2026-20765 (Incorrect comparison for some Intel(R) TDX Guest software
before versi ...)
@@ -9371,7 +9371,7 @@ CVE-2026-20739 (Improper conditions check for some
Intel(R) PROSet/Wireless WiFi
CVE-2026-20737 (Exposure of sensitive information to an unauthorized actor for
some In ...)
NOT-FOR-US: Intel
CVE-2026-20734 (Improper initialization in some firmware for some Intel(R)
Active Mana ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-20731 (Improper buffer restrictions for the Intel(R) NPU Driver for
all versi ...)
TODO: check
CVE-2026-20728 (Protection mechanism failure for some Intel Extension for
TensorFlow s ...)
@@ -9379,17 +9379,17 @@ CVE-2026-20728 (Protection mechanism failure for some
Intel Extension for Tensor
CVE-2026-20727 (Null pointer dereference for some Intel(R) PROSet/Wireless
WiFi Softwa ...)
NOT-FOR-US: Intel
CVE-2026-20715 (Improper input validation in some firmware for some Intel(R)
Active Ma ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-20712 (Incomplete cleanup in some UEFI firmware for some Intel(R)
reference p ...)
NOT-FOR-US: Intel
CVE-2026-20708 (Insertion of sensitive information into log file in the
subsystem for ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-20705 (Insecure storage of sensitive information in the Intel(R) TDX
module f ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-20702 (Protection mechanism failure for some Intel(R) Data Center
Attestation ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2026-20349 (A vulnerability in the Remote Access SSL VPN service for Cisco
Secure ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-19546 (A flaw was found in DBI. This is a fix for a partial fix for
CVE-2026- ...)
- libdbi-perl <not-affected> (Red Hat-specific backport issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513963
@@ -10461,13 +10461,13 @@ CVE-2026-55814 (Missing Authentication in Apache
Ranger Download APIs on version
CVE-2026-55799 (Remote Code Execution Vulnerability in
GraalScriptEngineCreator in Apa ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-48159 (use-reducer-async is a React useReducer with async actions.
Between 20 ...)
- TODO: check
+ NOT-FOR-US: use-reducer-async
CVE-2026-48158 (use-context-selector is a React useContextSelector hook in
userland Be ...)
- TODO: check
+ NOT-FOR-US: use-context-selector
CVE-2026-48048 (XWiki Platform is a generic wiki platform. XWiki discovered
that the p ...)
NOT-FOR-US: XWiki
CVE-2026-47754 (Metacat is data repository software that helps researchers
preserve, s ...)
- TODO: check
+ NOT-FOR-US: Metacat
CVE-2026-44630 (Improper validation of length fields in the Apache IoTDB RPC
service m ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-44416 (Remote Code Execution via Arbitrary Class Instantiation
inplugin-schem ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/320e60c9e8765e3e587a8286a9bf7eb9837e84b8
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/320e60c9e8765e3e587a8286a9bf7eb9837e84b8
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits